Описание
Silverstripe CMS XSS Vulnerability
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.
Пакеты
Наименование
silverstripe/cms
composer
Затронутые версииВерсия исправления
< 3.4.4
3.4.4
Наименование
silverstripe/cms
composer
Затронутые версииВерсия исправления
>= 3.5.0, < 3.5.2
3.5.2
Связанные уязвимости
CVSS3: 6.1
nvd
почти 9 лет назад
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2. The attack vector is a page name. An example payload is a crafted JavaScript event handler within a malformed SVG element.